generated: '2026-08-04' method: searched source: >- https://support.threatdown.com/hc/en-us/articles/4413798542995-Nebula-Product-Lifecycle, https://support.threatdown.com/hc/en-us/articles/36402439667475-April-3-2025-Nebula-and-OneView-console-domain-and-single-sign-on-update, https://status.threatdown.com/, and the harvested OpenAPI definitions versioning: scheme: path-prefixed major version pattern: /{product}/v{n}/... current: - api: nebula prefix: /nebula/v1 - api: oneview prefix: /oneview/v1 spec_version: 1.0.0 note: >- The URL path is versioned at v1 for both products while the spec's info.version is a flat 1.0.0 that does not move. There is no Accept-header, query-parameter or date-pinned version negotiation, and no published API version support window or end-of-life policy for a major version. New capability lands additively inside v1. status_page: published: true url: https://status.threatdown.com/ covers: - ThreatDown Nebula console - ThreatDown OneView console - ThreatDown APIs note: >- status.malwarebytes.com redirects to status.threatdown.com — one status property for the whole platform. deprecation: policy_published: false policy_url: null sunset_header: false deprecation_header: false rfc8594_compliant: false mechanism: >- Deprecation is signalled in-band only: the OpenAPI marks superseded operations with `deprecated: true`, and product-level end-of-life is announced in support-portal articles. No RFC 8594 Sunset header, no Deprecation header (RFC 9745), and no dated removal commitment accompanies a deprecated operation. product_lifecycle_url: https://support.threatdown.com/hc/en-us/articles/4413798542995-Nebula-Product-Lifecycle deprecated_operations: count: 6 api: oneview source: openapi/malwarebytes-threatdown-oneview-openapi.json note: >- The per-site subscription operations under /oneview/v1/sites/{id}/subscriptions are all marked deprecated. No replacement operation, sunset date, or migration note is carried on the operation objects themselves. operations: - operationId: api.v2.oneview.create.subscription.id method: POST path: /oneview/v1/sites/{id}/subscriptions - operationId: api.v2.oneview.delete.subscription.id method: DELETE path: /oneview/v1/sites/{id}/subscriptions - operationId: api.v2.oneview.get.subscription.id method: GET path: /oneview/v1/sites/{id}/subscriptions - operationId: api.v2.oneview.update.subscription.id method: PUT path: /oneview/v1/sites/{id}/subscriptions - operationId: api.v2.oneview.get.subscription.all method: GET path: /oneview/v1/sites/{id}/subscriptions/all - operationId: api.v2.oneview.get.master.subscription.id method: GET path: /oneview/v1/subscriptions migrations: - name: API and console domain migration to threatdown.com announced: '2025-04-03' from: api.malwarebytes.com to: api.threatdown.com console_from: cloud.malwarebytes.com console_to: cloud.threatdown.com breaking: false old_host_retired: false evidence: >- "The former API domain will continue to operate beyond April 3, 2025, but ThreatDown recommends updating your code to use the new API domain at your earliest convenience." source: https://support.threatdown.com/hc/en-us/articles/36402439667475-April-3-2025-Nebula-and-OneView-console-domain-and-single-sign-on-update observed_2026_08_04: >- Both hosts still answer. api.malwarebytes.com/nebula/v1/docs and api.threatdown.com/nebula/v1/docs both return 200, and the canonical spec URL the ReDoc page loads is still cloud.malwarebytes.com/api/v2/nebula/docs — the old brand domain remains load-bearing more than a year after the migration was announced. scope_note: >- This was a rebrand-driven host migration under the Malwarebytes → ThreatDown business rename, not an API version change. No path, payload or auth semantics changed. sla: published: false note: >- No public uptime SLA or API availability commitment is published. Availability terms are in the commercial agreement at https://www.threatdown.com/legal/terms-of-service/. support: channels: - type: support-portal url: https://support.threatdown.com/hc/en-us/ - type: community-forum url: https://forums.malwarebytes.com/ - type: contact url: https://www.threatdown.com/contact-us/ gaps: - No published deprecation policy document, notice period, or removal timeline. - No Sunset (RFC 8594) or Deprecation (RFC 9745) response headers on deprecated operations. - No replacement pointer on any of the 6 deprecated OneView subscription operations. - No published API SLA. - No roadmap page for the API. x-evidence: fetched: '2026-08-04' urls: - url: https://status.threatdown.com/ http_status: 200 - url: https://api.threatdown.com/nebula/v1/docs http_status: 200 - url: https://api.malwarebytes.com/nebula/v1/docs http_status: 200